Hey all, cleaning up another spyware infestation, and found something called "trvrcrh" residing in the WINNT\system32 folder that Google knows not.
I tried disabling it in MSCONFIG, but on next reboot, it had created another reference to itself. I could not find this file on any other Windows 2000 PC, so I tried deleting it. It was "in use" so I had to delete it from Safe Mode. Rebooted. It was back.
Ran HJT, "fixed" it, ran another log 10 seconds later. It was already back!
Anyway, it may possibly be tied into some piece of crap called "eBates Moe MoneyMaker" another spyware app I discovered on this PC which I was able to find info about, but none of the instructions I found worked on removing it.
I tried disabling it in MSCONFIG, but on next reboot, it had created another reference to itself. I could not find this file on any other Windows 2000 PC, so I tried deleting it. It was "in use" so I had to delete it from Safe Mode. Rebooted. It was back.
Ran HJT, "fixed" it, ran another log 10 seconds later. It was already back!
Anyway, it may possibly be tied into some piece of crap called "eBates Moe MoneyMaker" another spyware app I discovered on this PC which I was able to find info about, but none of the instructions I found worked on removing it.